Siemens Product Security Update Advisory

Siemens Product Security Update Advisory

Overview


Siemens has released a security update addressing several vulnerabilities discovered in its SICAM 8 products.

Affected Products


  • CPCI85 Central Processing/Communication: Versions prior to V26.20.
  • SICORE Base System version: Earlier than V26.20.0.

Resolved Vulnerabilities


  • CVE-2026-54798: Denial-of-service vulnerability in the HTTP debug interface.
  • CVE-2026-54799: A signature verification vulnerability occurring during the firmware signature verification process.
  • CVE-2026-54800: An unauthorized access vulnerability occurring in the default OPC UA security settings.
  • CVE-2026-54801: Privilege escalation vulnerability occurring during the authentication verification process when changing the administrator account.

Response


Vulnerability Patches are available in the latest update; users must update to the latest version with the Vulnerability Patches following the instructions on the reference site.

References


  • SSA-229470: Multiple Vulnerabilities in SICAM 8 Products Prior to V26.20.
  • Https://cert-portal.Siemens.Com/productcert/html/ssa-229470.Html